The attackers may take advantage of flaws in the Cockpit source code to carry out a kind of attack, such as getting access to any user account and reset passwords. In some configurations, the vulnerabilities might allow an attacker to execute code on a Cockpit server. The first flaw allows a NoSQL injection attack through the Controller/Auth.php search feature, and the second flaw allows for a NoSQL injection attack through the Controller/Auth.php reset password function.
We suggest you to update Cockpit to a version greater than 0.12.0 in order to fix this vulnerability.